Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


If a VPN profile cannot be removed, first determine who owns it. It may have been created manually, installed by a VPN app, enforced by always-on settings, attached to a work profile, or locked by mobile-device management. Use the owner's supported removal path; a missing or disabled delete button is not permission to bypass administration.
Key Takeaways
- Record the profile name, connection type, current status, and exact removal error before changing anything.
- Remove an app-owned profile from the app first; remove a user-created connection from operating-system VPN settings.
- Always-on or work-profile policy can recreate a connection after you delete the visible entry.[3]
- Some managed Apple profiles can be removed only by an administrator.[2]
- Do not delete certificates, drivers, registry keys, or management records merely because their names resemble the VPN.
See the complete VPN guide first if you need to separate the VPN client from the saved connection it controls.
“Profile” is used loosely across platforms. It can mean a saved VPN connection, a signed configuration profile containing several settings, or a policy delivered by an employer or school.
| Owner | Clues | Correct removal route |
|---|---|---|
| You created it manually | Editable server and account fields; no management label | OS VPN settings |
| A VPN application | Provider name, app-managed toggle, returns when app opens | Disconnect and remove inside the app, then uninstall if needed |
| Always-on system setting | Reconnects automatically; traffic may be blocked without VPN | Disable through the authorized always-on owner |
| Work profile or MDM | “Managed,” organization name, disabled controls | Organization portal or administrator |
| Imported configuration file | Installation record or signed profile details | Configuration-profile settings and issuer guidance |
Do not infer ownership from the icon alone. Record the profile's exact display name and any organization, signer, account, or app shown in its details.
Never export private keys, enrollment secrets, certificates, recovery codes, or full enterprise configuration merely to create a troubleshooting record.
Use the normal Disconnect control in the VPN app or OS settings. If the profile reconnects immediately, look for always-on, on-demand, or management policy. Do not repeatedly kill system services; that does not change who owns the configuration.
Open the client that installed the profile. Turn off auto-connect and use its remove, reset, sign-out, or uninstall workflow as documented by the vendor. Restart afterward and check whether the OS entry remains.
If two clients may be involved, use the two VPN apps conflict guide to inventory both before uninstalling either one.
On macOS, Apple documents selecting the VPN configuration in Network settings and choosing Remove Configuration.[1] On Windows, supported interfaces include VPN settings and the Remove-VpnConnection PowerShell cmdlet; command-line removal should target the exact confirmed connection name and the correct user or all-user scope.[4]
On Android, open the VPN entry's settings and use Forget where available. Android also documents always-on and work-profile controls, which can change whether a personal user may remove or disable the connection.[3] Menu names vary by device vendor, so match the ownership model rather than memorizing one screen path.
On Apple devices, a configuration profile may contain VPN, certificates, Wi-Fi, email, and other settings. Review what it controls before deletion. Removing the whole profile can remove more than the VPN connection.
Apple states that some Mac configuration profiles can be removed only by a system administrator.[2] If the profile shows an organization, supervision, or non-removable status, stop and contact that administrator.
After supported removal, restart the device. Confirm that the entry is gone, it does not return after a network change, ordinary networking works, and no unexpected proxy remains. Reinstall only the VPN client you actually intend to use.
Removing a profile and closing a provider account are different actions. If you plan to restore your personal connection afterward, verify that you can still sign in to the AethoVPN account you intend to retain before a broader reset. That sign-in cannot remove an operating-system profile, grant administrator rights, or override work-profile and MDM policy; the profile owner must authorize removal.
An app may recreate its profile at launch. An always-on controller can reassert the selected VPN. A device-management service can reinstall required settings after the device checks in. Restoring a backup can also restore configuration.
Use timing to identify the owner:
Repeatedly deleting the visible entry will not fix the policy or app that recreates it.
If you personally own the device but an old employer profile remains, contact the organization's IT team or the device vendor with proof of ownership. A legitimate de-enrollment process is safer than attempting to defeat the management control.
Use a network reset or full device erase only after the profile owner is known, supported removal has failed, necessary data is backed up, and management consequences are understood. On an enrolled device, an erase may automatically re-enroll it and restore the same profile.
Before any reset, confirm whether you can recover accounts, multi-factor authentication, eSIM service, Wi-Fi credentials, work enrollment, and the retained VPN configuration. If the profile is the only fault and networking otherwise works, escalation is usually lower risk than a broad reset.
Before replacing a VPN app, disable its automatic connection and use its documented profile-removal control. Keep the app installed until the OS confirms that its profile is gone. For imported profiles, retain the issuer name and removal instructions without storing embedded secrets.
When a device changes owner or leaves an organization, complete the approved de-enrollment while the previous administrator can still authorize it. A later factory reset may not help if automated enrollment assigns the device back to the same management service.
The connection may be active, app-owned, always-on, or managed by an organization. Check the profile details and owner before assuming the settings app is broken.
Often, but not always. First use the app's disconnect and removal controls, then uninstall through the supported OS path and restart.
An app, always-on rule, work profile, MDM service, or restored backup may recreate it. Note exactly when it returns to identify that owner.
Only through the organization-approved work-profile or enrollment process. Removing a work profile may also erase work apps and data, so review the policy and contact IT first.
Not without confirming their exact purpose and owner. A certificate may support several services, and deleting it can break identity, Wi-Fi, email, or work access.
Use it only when you understand the exact connection name and user scope. The supported cmdlet is precise, but a mistaken target can remove a different saved connection.[4]
Not necessarily. Automated enrollment may restore management and the required profile. A reset can also erase data and authentication access, so it is not a shortcut around administration.
Send the device and OS version, profile name, ownership indicators, exact error, and timestamps. Redact server secrets, usernames, certificate data, enrollment tokens, and account identifiers.
Disclaimer: This guide does not authorize bypassing device management, administrator controls, employer policy, or access restrictions. Follow the profile issuer's approved process.
Sources:
Remove-VpnConnection: https://learn.microsoft.com/en-us/powershell/module/vpnclient/remove-vpnconnection?view=windowsserver2025-psSources checked 6 September 2026.
Related Articles:
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.